CH20 - Course Quiz Flashcards

1
Q

A packet sniffer is a program that queries a network interface and collects packets in a file called a ______________ file?

capture
log
flow cache
syslog

A

capture

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

In NetFlow, flows are stored in a _____________?

log
flow cache
packet
frame

A

flow cache

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

An agent can solicit information from an NMS with the ____________ protocol data unit (PDU)?

set
get
response
trap

A

trap

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

It is a good idea to give root access to critical log files for performance reasons?

True
False

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

The SNMP Manager requests and processes information from the ____________ devices?

opened
closed
managed
privileged

A

managed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which underlying protocol enables network monitoring tools to work?

TCP
SNMP
UDP
SMTP

A

SNMP (Simple Network Management Protocol)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

A single flow in NetFlow is a sequence of packets from one specific place to another?

True
False

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which program is an example of a powerful and open source protocol analyzer?

wireshark
syslog
cisco network assistant (CNA)
PerfMon

A

Wireshark

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

On which port does NMS receive/listen?

160
161
162
163

A

162 (Network Management System)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Which tool was developed for packet flow monitoring and was subsequently included in Cisco Routers and Switches?

NetFlow
Wireshark
PerfMon
Syslog

A

NetFlow

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Interface monitors track the quality and utilization of traffic through a physical _____________ or ports on a single device?

network interface card (NIC)
port
switch
frame

A

port

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

In the case of a Switch, it is typical for packet sniffers to connect to an interface using a _____________ port?

virtual
mirrored
promiscuous
closed

A

mirrored

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Which one function is sent when an SNMP Manager wants to query an agent?

Set
Get
Response
Trap

A

Get

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which term does Performance Monitor use when referring to the monitored aspect of the System?

facilities
counters
modes
characteristics

A

counters

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

The current version of SNMP is SNMPv3?

True
False

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Which tool is used to create a baseline on Windows Systems?

Performance Monitor
Cacti
Syslog
NetFlow

A

Performance Monitor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What User Datagram Protocol (UDP) ports does SNMP use for unsecure communication?

61 and 62
610 and 612
161 and 162
10162 and 10161

A

161 and 162

Explanation:
Secure TLS SNMP = 10161 and 10162

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Which program is an example of graphing tool that could be used to show everything about specific switches?

NetFlow
Cacti
Syslog
Cisco Network Assistant (CNA)

A

Cacti

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

An SNMP System has up to ______________ core functions (depending on the version of SNMP)?

two
four
six
eight

A

eight

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Performance Monitors use system ____________ files to track performance over time?

Access Control List (ACL)
flow cache
routing table
log

A

log

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Which core function is sent by the agent after the SNMP manager queries an agent with a GetRequest or GetNextRequest?

Set
Get
Response
Trap

A

Response

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Which sensors monitor environmental factors, such as external temperatures, humidity levels in the server room, issues with electrical load, and more?

interface
environmental
response
trap

A

environmental

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

All operating systems come with some form of baseline tools?

True
False

24
Q

NetFlow is another name for SNMP?

True
False

25
Which interface statistic value increases when packets are received that are shorter than Ethernet's minimum size of 64 bytes? encapsulation link runts giants
runts
26
An NMS can tell an agent to make changes to the information it queries and sends, called variables, through a ________________ protocol data unit (PDU)? Set Get Response Trap
Set
27
Managed devices run software called ________________? robots switches drones agents
agents
28
In NetFlow, a single flow is a sequence of _________________ from one specific place to another? frames packets segments cylinders
packets
29
If you want to know how hard your network is working, us a ________________? management information base flow cache performance manager interface monitor
interface monitor
30
A ___________ is a centralized location for technicians and administrators, used to manage all aspects of the Network?
Network Operations Center (NOC)
31
On an SNMP managed network, a _________________ program could create graphs and diagrams that display any set of the data received?
graphing
32
SNMP adds security using _______________?
Transport Layer Security (TLS)
33
In packet flow monitrong, a single __________________ is a sequence of packets from one specific place to another?
flow
34
With interface monitoring, ___________________ references how much of the port's total bandwidth is being used?
utilization
35
______________________ track the bandwidth and utilization of one or more interfaces on one or more devices?
Interface Monitor
36
The most common macOS and Linux Performance Monitor tool is called ___________________?
Syslog
37
A ____________________ tracks the performance of some aspect of a system over time and lets you know when things aren't normal?
Performance Monitor
38
__________________________ are the computers within a Network that are receiving the most data?
Top Listeners
39
SNMP uses _______________________ to categorize the data that can be queried (and subsequently analyzed)?
Management Information Bases (MIB)
40
The ____________________ is the defacto network management protocol for TCP/IP Networks?
Simple Network Management Protocol (SNMP)
41
The _________________ utility can quickly query any SNMP device directly from a computer's terminal?
snmpwalk
42
The common term for each of the SNMP System core functions is ________________?
Protocol Data Unit (PDU)
43
Describe the ports SNMP uses for unsecure and secure communications?
SNMP Managers use UDP Ports 162 or 10162 with Transport Layer Security (TLS). SNMP Agents use Ports 161 or 10161 with Transport Layer Security (TLS).
44
List the four major types of monitoring tools?
Packet (Sniffers) Protocol (Analyzers) (Interface) Monitors (Performance) Monitors
45
Describe a baseline and explain how a baseline can point to problems on a Server or the Network?
A Baseline is a log of normal operational performance to give you a picture of your network and servers when they are working correctly. A major change in these values can point to problems on a server or network as a whole.
46
How should an administrator enable NetFlow in order to use it?
NetFlow is Enabled on the Device, if the device doesn't support NetFlow, you can use stand-alone probes that can monitor maintenance ports on the unsupported device and send the information to the NetFlow collector.
47
Identify three components in a Managed Network?
Managed (Devices) SNMP (Manager) SNMP (Agent)
48
Describe the two most common performance monitor tools?
Windows Performance Monitor (perfmon.exe) | Syslog (found in macOS and Linux)
49
What are SNMP Alerts and how are they disseminated?
Alerts, Notifications - they are sent directly to techs - via SMS text messaging and email alerts - when their intervention is required.
50
Describe the key component that enables performance monitors to track performance over time?
Logs - They store information about the performance of some particular aspect of a system.
51
Briefly list the versions of SNMP?
SNMPv1 SNMPv2 SNMPv3
52
Explain the purpose of applications like Cacti?
They enable you to see very quickly essential facts about your Network Hardware.
53
Briefly describe a packet sniffer?
It's a program that queries a Network interface and collects packets in a file called a capture file. Might sit on a single computer or perhaps on a Router or a dedicated piece of hardware.
54
Explain why access to active logs must be carefully controlled and explain how this can be accomplished?
Because logs often contain private or sensitive data.
55
Identify additional terms for utilities that analyze packets?
Packet (Sniffer) (Packet) Aalyzer (Protocol) Analyzer (Network) Analyzer